Johnson & Johnson

Professional, Quality Steward

Johnson & Johnson$79K — $142K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Software/Biomedical/Electrical Engineering, or related discipline.
  • Master's degree in Cybersecurity, Computer Science, or Biomedical Engineering preferred.
  • 4+ years of experience in product security or related cybersecurity engineering discipline.
  • Experience applying Secure by Design principles across a product development lifecycle.
  • Hands-on experience with threat modeling methodologies such as STRIDE or attack trees.
  • Working knowledge of coding practices and application security testing tools.
  • Strong communication skills to articulate security risks to various stakeholders.

Responsibilities

  • Serve as the product security steward for product lines, embedding Secure by Design principles throughout development.
  • Define and document security requirements and design inputs in collaboration with cross-functional teams.
  • Facilitate threat modeling and security architecture reviews for various connected devices and software.
  • Conduct product security risk assessments to integrate cybersecurity with product risk management.
  • Generate and manage Software Bills of Materials while monitoring third-party vulnerabilities.
  • Support secure software development practices, including integrating security into CI/CD pipelines.
  • Prepare cybersecurity documentation for regulatory submissions, ensuring compliance with multiple international requirements.

Benefits

  • Participation in the Company's consolidated retirement plan and 401(k).
  • Generous vacation time (120 hours per year) along with sick time and holiday pay.
  • Parental leave (480 hours) and caregiver leave (80 hours in a rolling period).
  • Flexible personal and family time off allowances.
  • Volunteer leave (32 hours annually) and military spouse time-off.
  • Additional paid time for bereavement and floating holidays.
Full Job Description
Job Function:
Technology Product & Platform Management

Job Sub Function:
Technical Product Management

Job Category:
Scientific/Technology

All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a Professional, Quality Steward located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA.

Job Overview

The Professional, Quality Steward is an established and productive individual contributor within the Cybersecurity function, accountable for embedding Secure by Design principles into the DePuy Synthes medical device and connected product portfolio. This role serves as the quality and security steward across the total product lifecycle - partnering with R&D, Product Management, Engineering, Regulatory Affairs, and Quality to ensure security requirements are defined early, designed in, verified through testing, and sustained through postmarket monitoring. Working under moderate supervision, the analyst applies practical knowledge of product security, secure development practices, and medical device regulatory expectations to ensure products are safe, secure, compliant, and defensible to regulators and customers.

Key Responsibilities

  • Serve as the product security steward for assigned product lines, embedding Secure by Design requirements into the product development lifecycle from concept through end-of-support.


  • Define and document security requirements, design inputs, and acceptance criteria in collaboration with product owners, systems engineers, and R&D teams during early design phases.


  • Facilitate threat modeling and security architecture reviews for connected devices, embedded software, mobile applications, and supporting cloud services; ensure identified threats are mitigated and traceable to controls.


  • Conduct and coordinate product security risk assessments aligned to AAMI TIR57 and ISO 14971, ensuring cybersecurity risk is integrated with overall product risk management files.


  • Generate, validate, and maintain Software Bills of Materials (SBOMs) for products; monitor third-party and open-source components for known vulnerabilities and drive remediation planning.


  • Support secure software development practices, including secure coding standards, static and dynamic analysis, dependency scanning, and integration of security gates into CI/CD pipelines.


  • Coordinate penetration testing and security verification activities with internal teams and third-party assessors; triage findings, assess exploitability and patient safety impact, and track remediation to closure.


  • Prepare and review cybersecurity documentation for regulatory submissions, aligned to FDA premarket cybersecurity guidance, EU MDR, and applicable international requirements.


  • Operate postmarket vulnerability management for released products - monitoring threat intelligence, performing impact analysis, and supporting coordinated vulnerability disclosure and customer advisories.


  • Develop and maintain customer-facing security artifacts, including MDS2 forms, security white papers, and responses to hospital and health system security assessments.


  • Partner with Quality and Regulatory to ensure product security activities are captured in design history files, design controls, and the Quality Management System.


  • Establish and report product security metrics - design review coverage, vulnerability aging, SBOM currency, and remediation SLA performance - to leadership and program stakeholders.


  • Assess security implications of product changes, platform migrations, supplier changes, and separation/carve-out activity affecting the product portfolio.


  • Deliver Secure by Design training and enablement to engineering and product teams to strengthen security ownership and cyber culture.


Qualifications

Education

  • Bachelor's degree in Computer Science, Cybersecurity, Software/Biomedical/ Electrical Engineering, Information Systems, or a related technical discipline.


  • Master's degree in Cybersecurity, Computer Science, or Biomedical Engineering.


Experience and Skills

Required:

  • 4+ years of experience in product security, application security, secure software development, or a related cybersecurity engineering discipline.


  • Demonstrated experience applying Secure by Design principles across a product development lifecycle, including security requirements definition and design review.


  • Hands-on experience with threat modeling methodologies (e.g., STRIDE, attack trees) for embedded, mobile, or connected systems.


  • Working knowledge of secure coding practices, common vulnerability classes (OWASP Top 10, CWE), and application security testing tools (SAST, DAST, SCA).


  • Experience with vulnerability management, including CVE analysis, CVSS scoring, and risk-based remediation prioritization.


  • Familiarity with SBOM generation, formats (SPDX, CycloneDX), and third-party/open-source component risk management.


  • Strong written and verbal communication skills, with the ability to explain security risk to engineering, quality, regulatory, and commercial stakeholders.


Preferred:

  • MedTech or medical device experience; working knowledge of FDA premarket and postmarket cybersecurity guidance, EU MDR, IEC 62304, ISO 14971, ISO 13485, and AAMI TIR57/TIR97.


  • Experience preparing cybersecurity content for regulatory submissions and responding to agency questions.


  • Experience supporting product security within a divestiture, carve-out, or standalone entity stand-up.


  • Familiarity with embedded systems security, firmware analysis, secure boot, cryptographic key management, and hardware root of trust.


  • Experience with cloud and connected-platform security (AWS, Azure), API security, and IoT/IoMT architectures.


  • Exposure to coordinated vulnerability disclosure programs and customer security assessment response (MDS2, HSCC guidance).


  • Experience applying Generative AI / LLM-enabled tooling to accelerate code review, threat modeling, and security documentation.


  • Familiarity with DevSecOps toolchains and integrating security gates into CI/CD pipelines.


Other:

  • Travel: Up to 10% domestic and international travel expected across DePuy Synthes sites.


  • Language: English proficiency required.


  • Certifications: CSSLP, GWAPT, OSCP, CEH, CISSP, or equivalent product/application security certification preferred.


Required Skills:

Preferred Skills:
Analytical Reasoning, Coaching, Communication, Cross-Functional Collaboration, Demand Forecasting, Human-Computer Interaction (HCI), Persistence and Tenacity, Product Costing, Product Development, Product Strategies, Quality Assurance (QA), Research and Development, Researching, Software Development Management, Technical Credibility, Technologically Savvy

The anticipated base pay range for this position is :
79,000.00 - 142,000.00 USD Annual

Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation -120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year • Holiday pay, including Floating Holidays -13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave - 80 hours in a 52-week rolling period10 days • Volunteer Leave - 32 hours per calendar year • Military Spouse Time-Off - 80 hours per calendar year For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Healthcare Jobs

Find similar Professional, Quality Steward jobs: